2021-08-02 16:17:48 +00:00
id : CVE-2020-27361
info :
name : Akkadian Provisioning Manager - Files Listing
author : gy741
severity : high
description : An issue exists within Akkadian Provisioning Manager 4.50.02 which allows attackers to view sensitive information within the /pme subdirectories.
reference : https://www.blacklanternsecurity.com/2021-07-01-Akkadian-CVE/
tags : cve,cve2020,akkadian,listing,exposure
2021-09-10 11:26:40 +00:00
classification :
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score : 7.50
cve-id : CVE-2020-27361
cwe-id : CWE-668
2021-08-02 16:17:48 +00:00
requests :
- method : GET
path :
- "{{BaseURL}}/pme/media/"
matchers-condition : and
matchers :
- type : word
words :
- "Index of /pme/media"
- "Parent Directory"
condition : and
- type : status
status :
- 200